Emergent-Threat CVE Automation

How Guard alerts you when a new high-risk CVE is scanned for, found in your environment, and proven exploitable.

When Praetorian deploys a new detection template for a critical CVE, Guard can notify you in up to three steps: when scanning for the CVE starts, when the CVE is found in your environment, and when a Hannibal hunt proves it is exploitable.

Praetorian turns these notifications on for your account. Contact your Praetorian team to enable them. Accounts without them enabled get Guard's standard new-risk notification when the CVE is found.

Which CVEs qualify

A CVE starts this sequence when its detection template is deployed and the CVE meets either condition:

  • It is on the CISA Known Exploited Vulnerabilities list.
  • Its EPSS probability is 60% or higher.

The three notifications

1. Security advisory

Guard emails a security advisory when scanning for the CVE starts. The subject is [Praetorian Guard Security Advisory] Critical Vulnerability <CVE ID>. Guard sends it once per CVE.

2. Detection

When the CVE is found on one of your assets as a new open risk, Guard sends Praetorian Guard Emergent Threat Detection instead of the standard new-risk notification. The email subject is [Praetorian Guard] <CVE ID> Detected in Your Environment. The message lists:

  • the CVE, its CVSS score and EPSS probability;
  • CISA Known Exploited Vulnerability and Public Exploit Available, when they apply;
  • the risk, asset, and severity;
  • a View Risk link.

Ticketing integrations receive the risk as a regular ticket.

3. Exploitation proven

When the CVE is detected, Guard also tries to start a Hannibal hunt against the finding. The hunt runs for up to 24 hours at aggressive settings. It starts only when:

  • AI Autonomy and Automatic Penetration Tests are on (see Automatic Penetration Tests);
  • no other hunt is running;
  • the account has AI budget headroom.

If the hunt exploits the vulnerability and files evidence, Guard sends Praetorian Guard Emergent Threat — Exploitation Proven. The email subject is [Praetorian Guard] <CVE ID> Exploitation Proven in Your Environment. The message has the same details as the detection notification.

What to do

Notification

Action

Security advisory

Check whether you run the affected technology. No action is needed in Guard.

Detection

Open the risk with View Risk and start remediation.

Exploitation proven

Treat the risk as confirmed. Review the hunt's evidence on the risk and escalate through your incident process.